Back

CRITICAL

curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service

Published May 24, 2018

Description

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.

Affected products

Remediation

No remediation recorded yet.

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 24, 2018
Updated Apr 15, 2026
Reserved May 6, 2018
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 16, 2018
ENISA EUVD
Assigner mitre
Published May 24, 2018
Updated Apr 15, 2026
Exploited since n/a
EUVD-2018-1896